Re: [patch] alignment trap in hcid

Frédéric Dalleau <[email protected]>
Newsgroups gmane.linux.bluez.devel
Message-ID <[email protected]>
Damn me, I always forget this space after ifs...
Is there any way to test this, or hope it's ok ?

Frederic

Johan Hedberg wrote:
> On Feb 29, 2008, at 20:27, Marcel Holtmann wrote:
>   
>>> I recently met an alignment trap in hcid.
>>> Some device sent me an sdp request and the answer had to be
>>> fragmented because the device reception buffer was very small.
>>> After that i saw alignment trap.
>>> The last trace I saw was : Continuation state size: 8
>>> The trace is located at sdpd/request.c : static sdp_cont_state_t
>>> *sdp_cstate_get(uint8_t *buffer)
>>> This function returns an unaligned pointer.
>>>       
>> this is so funny since I know it was there, but the new qualification
>> tests don't find it anymore :)
>>
>> Please fix the coding style. You are missing some spaces after the  
>> "if".
>>
>> Johan, please have second look at the patch. It looks good to me.
>>     
>
> Looks good to me too.
>
> Johan
>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Microsoft
> Defy all challenges. Microsoft(R) Visual Studio 2008.
> http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
> _______________________________________________
> Bluez-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/bluez-devel
>

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/

_______________________________________________
Bluez-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/bluez-devel
upf_hcid_align.patch (text/x-patch, 1.2 KB)
diff --git a/sdpd/request.c b/sdpd/request.c
index 20e68b6..5e3c715 100644
--- a/sdpd/request.c
+++ b/sdpd/request.c
@@ -179,7 +179,10 @@ static sdp_cont_state_t *sdp_cstate_get(uint8_t *buffer)
 
 	pdata += sizeof(uint8_t);
 	if (cStateSize != 0) {
-		sdp_cont_state_t *cstate = (sdp_cont_state_t *)pdata;
+		sdp_cont_state_t *cstate = malloc(sizeof(sdp_cont_state_t));
+		if (!cstate)
+			return NULL;
+		memcpy(cstate, (sdp_cont_state_t *)pdata, sizeof(sdp_cont_state_t));
 		debug("Cstate TS : 0x%lx", cstate->timestamp);
 		debug("Bytes sent : %d", cstate->cStateValue.maxBytesSent);
 		return cstate;
@@ -408,6 +411,8 @@ static int service_search_req(sdp_req_t *req, sdp_buf_t *buf)
 	}
 
 done:	
+	if (cstate)
+		free(cstate);
 	if (pattern)
 		sdp_list_free(pattern, free);
 
@@ -593,6 +598,8 @@ static int service_attr_req(sdp_req_t *req, sdp_buf_t *buf)
 	buf->buf_size += sizeof(uint16_t);
 
 done:
+	if (cstate)
+		free(cstate);
 	if (seq)
                 sdp_list_free(seq, free);
 	if (status)
@@ -754,6 +761,8 @@ static int service_search_attr_req(sdp_req_t *req, sdp_buf_t *buf)
 	}
 
 done:
+	if (cstate)
+		free(cstate);
 	if (tmpbuf.data)
 		free(tmpbuf.data);
 	if (pattern)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.